CVE-2026-53822

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) OpenClaw anterior a 2026.5.18 contiene una vulnerabilidad de inyección de comandos donde el argv del wrapper de shell podría cambiar entre la aprobación y la ejecución. Los atacantes pueden reconstruir los argumentos de comandos después de la aprobación de la lista de permitidos para ejecutar estructuras de comandos no aprobadas, eludiendo potencialmente los controles de seguridad.

16 Jun 2026, 02:52

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-2j8v-hwgc-x698 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-2j8v-hwgc-x698 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-command-argument-modification-via-shell-wrapper-between-approval-and-execution - () https://www.vulncheck.com/advisories/openclaw-command-argument-modification-via-shell-wrapper-between-approval-and-execution - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
CWE CWE-77

12 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 22:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-53822

Mitre link : CVE-2026-53822

CVE.ORG link : CVE-2026-53822


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')